PT-2026-68377 · Unknown · Hermes-Agent
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
hermes-agent versions prior to 0.16.1
Description
An issue exists in the Memory Toolset component within the
hermes-agent/model tools.py file. This flaw allows remote attackers to bypass access controls through manipulation of unknown functionality.Recommendations
Update hermes-agent to a version later than 0.16.0.
Restrict access to the
hermes-agent/model tools.py file to minimize the risk of exploitation.Exploit
Fix
Incorrect Privilege Assignment
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hermes-Agent